The individual commands that the Agent Client Collector executes on the host are known as what? (Choose three.)
AEvents
BChecks
CParameters
DPolicies
EMetrics
FScripts
CIS-EM Practice Exam — Free 125+ Questions | ExamCademy
What is Event Management licensing based on?
AThe number of unique nodes that can send events to the instance
BThe number of connectors and listeners it will collect data from
CThe number of connectors it will collect data from
DThe number of CIs in the CMDB that it will be monitoring
The additional information field is a JSON string that gives more information about an event. An example of a supported JSON string is:
A{"CPU":100}
B{"CPU":100,’Status":3}
C{"CPU":"100","Status":3}
D{"CPU":"100"}
The Event Management operator workspace can display all of the following except?
AAlert groups
BManual application services
CDiscovered application services from Service Mapping
DCorrelation groups
ETechnical services
What would be the primary use case for creating Javascripts in Event Management?
ATo create a customized pull connector to retrieve events on behalf of an event source
BTo automatically populate the Configuration Management Database (CMDB)
CTo parse a nodename out of your raw event data in an event rule
DTo run as part of a remediation workflow for IT alerts that fail to execute
You have a very large networking environment and have noticed that your event notifications are either not being triggered or are delayed.
What are best options to try to resolve this issue? (Choose two.)
AEnsure all Event Management – process events jobs are set to a Ready state
BVerify that the Bucket field in the event table is set to zero (0)
CAdd additional event processor jobs
DEnsure multi-node event processing is disabled
When are anomaly alerts generated by Operational Intelligence displayed in alert intelligence?
AWhen the statistical model threshold is breached
BWhen they are promoted to IT alerts
CWhen it is manually promoted in insights explorer
DWhen the anomaly score is greater than 100
A Service is not viewable in Operator Workspace. What could be the issue?
AThe service is a manual service
BThe service is not set to operational
CThe service was created through Service Mapping
DThe service is a technical service
You have an event with a Source of ‘Trap from Enterprise 111’, but the alert created for this event shows a Source of ‘Oracle EM’. If you want to change what this is set to, where in the event rule would you do this?
ATransform and Compose Alert Output lab
BEvent rule info tab
CCI Binding tab
DEvent Filter tab
What makes all ServiceNow metrics, tasks, services, configuration items, assets, people, locations, and information a single system of record for IT and business processes?
AServiceNow is installed within your datacenter providing you complete control
BAll applications are built on the Oracle database standard, providing uniformity across products
CAll applications that are built by ServiceNow utilize the same data model and code base
DServiceNow runs on supported Windows servers and is managed through Windows Update
EA single table houses all data elements within ServiceNow
FServiceNow utilizes the AWS MariaDB cloud database structure, providing a single system of record
When creating an alert management rule, where would you specify a workflow to resolve a given condition?
AFrom the Remediation tab
BFrom the Actions tab
CFrom the Launcher tab
DIn the Related Links section
What types of system can a MID Server install on? (Choose two.)
AOpenVMS System
BMicrosoft Windows Server
CLinux System
DMicrosoft Windows Desktop
EAny system inside the customer firewall
FMac OS X System
What would you use to define the monitoring sources allowed to communicate with the ServiceNow instance for Operational Intelligence?
AMetric Registration
BMetric Config Rules
CMetric Type Actions
DMetric to CI
The value of the Alert Priority score is a composite of what?
AThe value of the alert’s category and its relative weight
BThe value of the alert’s category and its Priority Group
CThe value of the alert’s Severity and its Priority Group
DThe value of the alert’s Severity and its relative weight
Which attribute is responsible for de-duplication?
AMetric_name
BMessage_key
CShort_description
DAdditional_info
What is the default collection/polling interval applied to all event connectors?
AEvery 120 seconds
BEvery 5 seconds
CEvery 40 seconds
DEvery 60 seconds
EEvery 10 seconds
What feature would you use to trigger a workflow or automatically generate tasks via templates?
AEvent rules
BTask rules
CAlert management rules
DAlert correlation rules
What are the valid states an alert can be in during its lifecycle?
AOpen, Reopen, Flapping, Closed
BNew, Updating, Waiting, Complete
COpen, Updating, Swinging, Closed
DOpen, Warning, Flapping, Clear
What Event Management module allows for configuration of automatic task creation?
AAlert management rules
BTask rules
CEvent rules
DAlert correlation rules
You have a system configured with a MID Web Server using Basic authentication to enable Operational Management Intelligence (OI) to push raw metric data to the MID Server. No data is getting through to the MID Server.
What is the most likely cause of the issue?
AThe MID Web Server needs to be Restarted
BThe MID Web Server needs to be Started
CAn invalid secret key is being passed in the header information of the URL for the REST request
DAn invalid password is set in the MID Web Server Context
In the event table, which field maps the external attributes from the target system?
AResource
BDescription
CSource
DAdditional Information
By default, the Alert Console displays what type of alerts?
AAll Primary, Open alerts and anomaly alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode
BAll Primary and Secondary Open alerts and anomaly alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode
CAll Primary alerts with a Severity of Critical, Major, Minor, Warning that are not in Maintenance mode
DAll Primary, Open alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode
EAll Primary and Secondary Open alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode
Which are recommended best practices for Event Management? (Choose three.)
AFilter out events on ServiceNow Instance for easier consolidation and aggregation.
BPromote all events to alerts during initial implementation until you fully understand which should be ignored.
CFilter out events at source rather than in the ServiceNow instance.
DBase-line “normal-state” events to filter out background noise.
EIgnore all non-critical events during initial implementation to streamline processing; add alerts over time as time and resources allow.
For an incoming event with a matching message key, what allows an existing alert to be automatically closed?
AIn the event rule, set the Severity to 0
BIn the alert rule, set the Severity to 0
CIn the alert rule, set the Severity to -1
DIn the event rule, set the Severity to -1
A support agent resolves an incident associated with an alert, but the alert does automatically close even though the evt_mgmt.incident_closes_alert property is set appropriately to close the alert.
What is the most likely cause of this issue?
AThe support agent does not have the evt_mgmt_user role.
BThe support agent only has the evt_mgmt_admin role.
CThe support agent has the evt_mgmt_operator role, but not the evt_mgmt_user role.
DThe support agent has the evt_mgmt_user role, but not the evt_mgmt_operator role.